Senior Cybersecurity Engineer (IAM
Listed on 2026-08-09
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Amentum is a global leader in advanced engineering and innovative technology solutions, trusted by the United States and its allies to address their most significant and complex challenges in science, security and sustainability. Our people apply undaunted curiosity, relentless ambition and boundless imagination to challenge convention and drive progress. Our commitment s are underpinned by the belief that safety, collaboration and well-being are integral to success.
Headquartered in Chantilly, Virginia, we have approximately 50,000 employees in more than 70 countries across all 7 continents.
Amentum is seeking a Senior Cybersecurity Enginee
r with deep Identity and Access Management (IAM) expertise to protect enterprise assets across a multi-tenant, hybrid (cloud/on-premises) environment. This is a fully remote, hands-on role spanning identity security, multi-cloud security, and endpoint protection.
This position is US Remote telework and US Citizenship is required.
- Implement and operate enterprise IAM security controls across a multi-tenant/multi-domain hybrid environment spanning Entra , Okta, and Active Directory — including PAM, JIT access, conditional access, and MFA policy enforcement (not day-to-day user/group provisioning or account administration)
- Execute IAM designs defined by security architecture, translating architectural standards into working security configurations, policies, and integrations
- Maintain and enforce IAM-related security policies, standards, and best practices in alignment with regulatory and compliance requirements (CMMC, NIST 800-171/800-172, and other applicable frameworks)
- Configure and tune identity security controls — access policies, privileged access workflows, authentication requirements — protecting users, systems, applications, and data across Entra , Okta, and AD environments
- Serve as 2nd-level SOC escalation point for critical identity-related security incidents
- Investigate identity-related security anomalies using platform reporting, network traffic, log files, and automated alerts
- Support audit and assessment activities by maintaining compliant configurations and evidence for IAM controls
- Automate recurring IAM security operations tasks
- Maintain system and process documentation, including compliance-relevant control documentation
- Provide off-hours support as needed (infrequent)
- Cover other assignments as needed
- Working knowledge of Zero Trust, RBAC, and ABAC
- Working knowledge of regulatory/compliance frameworks relevant to IAM (CMMC, NIST 800-171/800-172, or similar)
- Understanding of network security fundamentals: boundary protection, segmentation, firewalls, endpoint security, threat hunting, data protection
- Self-starter, strong written/verbal communication, comfortable with minimal supervision and shifting priorities
- Ability to travel up to 10%
- Typically, 8 years of hands-on IAM security engineering experience with a Bachelor’s degree in Computer Science, Information Systems or related field plus; 4 with Master’s. IAM security engineering experiences includes implementing access controls, privileged access management, and authentication policy, rather than general user/account administration.
- Hands-on experience securing and administering Entra , Okta, and Active Directory identity infrastructure in a hybrid environment
- Solid experience in Privileged Access Management (PAM), Self-Service Password Management, and Just-In-Time (JIT) access
- Current CISSP, CISM, or equivalent certification
- Solid MFA and access-protection implementation experience
- Solid Microsoft Azure/M365 experience
- U.S. Citizen (required)
- Experience implementing an IAM governance platform such as Saviynt, SailPoint, or similar
- Experience supporting CMMC assessments or audits
- Familiarity with GDPR, SOX, ISO 27001
- Entra/Azure GCC High exposure
$120k-$149k
The compensation range or hourly rate listed for this position is provided as a good-faith estimate of what the company intends to offer for this role at the time this posting was issued. Actual compensation may vary based…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).